Lumi Clinic, by Heart Bridge Health Pty Ltd. Last updated: 2026-05-11.
This page describes how Lumi Clinic handles data specific to this product. For Heart Bridge Health's broader privacy practices, see the Heart Bridge Health master Privacy Policy.
When you create a clinic account we collect: your email address, clinic name, clinic address, contact name, and clinic attributes (state, MM classification, DPA status, accreditation, supervisor status). These are used to personalise responses and to gate access (approved clinics + subscription state).
When you chat with Lumi, we store the messages you send and the AI's responses against your clinic account. We also log queries (anonymised at the body level) to monitor quality and identify gaps in the knowledge base.
When you run an eligibility check, the doctor attributes you enter (country, registration status, pathway, fellowship status, moratorium status) are stored against your clinic account along with the generated report.
Conversation history, account details, and eligibility reports are stored in Supabase (PostgreSQL) hosted on Australian infrastructure. Embeddings used for knowledge retrieval are computed by OpenAI's API but are not used to train OpenAI's models (we use the data-retention-off tier). AI responses are generated by Anthropic Claude under their zero-data-retention policy.
Your conversations are scoped to your clinic account. Other clinics cannot see your data — database row-level-security policies deny all access to the public anon role.
Heart Bridge staff can access conversations only for:
We do NOT share conversation data with third parties for marketing, training, or analytics purposes.
Your conversations are never used to train AI models — neither ours, nor OpenAI's, nor Anthropic's. Both providers operate under enterprise terms that exclude API inputs from training.
Conversations are retained as long as your account is active. Deleted threads are soft-deleted for 30 days (recoverable via support) before permanent purge. If you delete your account, all personally identifiable data is purged within 30 days; anonymised analytics events (no clinic identifier) may be retained for service quality.
Multi-factor authentication is mandatory for all Lumi Clinic accounts. All traffic is encrypted in transit (HTTPS). Data at rest is encrypted by Supabase. API routes enforce per-request authentication and AAL2 (post-MFA) checks on every sensitive endpoint.
Under the Australian Privacy Principles you can:
To exercise any of these rights, email team@heartbridgehealth.com.au.
We use cookies for authentication (required) and, with your consent, marketing pixels (Meta Pixel, Google Ads) for re-engagement campaigns. Cookie consent is requested on first visit and can be changed at any time via the consent banner. No tracking pixels fire before consent is given.
We'll update this page when we change our practices, and we'll bump the "Last updated" date at the top. Material changes will also be announced via email to active users.
In the spirit of reconciliation, Heart Bridge acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.